Are SEO poisoning warnings warranted for Google Instant?

A security researcher has suggested Google Instant will aid Black Hat SEO attacks, but how concerning are his assertions?

Google

ANALYSIS When tech giants launch impressive new products, they will often come under the scrutiny of security professionals.

Thus it should come as no surprise a security researcher has warned the new Google Instant search function could help improve hackers SEO campaigns.

Blackhat SEO threats use illicit methods to place malicious sites higher up on search rankings, and PandaLabs' Sean-Paul Correll has said Google Instant could help improve such methods.

Advertisement - Article continues below

"We know for a fact that most Blackhat SEO campaigns automatically query Google's trending topic results and now it seems that Google Instant will be suggesting those trending phrases (verbatim), potentially putting millions of victims directly in cyber criminals' cross hairs," Correll claimed.

The researcher tried a search for "antivirus" and found Antivir Solution Pro, a notorious rogueware infection, was one of the suggested search terms.

Of course, the previous version of Google search already suggested what was popular among web users when information was entered, similar to what Instant does. Therefore, one could query whether there is actually much difference between the new and older versions in terms of assisting malicious website creators.

In response to the concerns, a Google spokesperson simply told IT PRO the change did not impact the ranking of search results.

Advertisement
Advertisement - Article continues below

"As with all changes to search, there will always be people who work to optimise their pages to fit the Google experience. There are no ranking changes with this enhancement and as always we continue to focus on showing user high-quality, relevant queries and search results," the spokesperson added.

Advertisement - Article continues below

There was no specific mention of SEO poisoning from Google.

A mini comparison

Luis Corrons, technical director of PandaLabs, told IT PRO he had tried out search on Google and Bing to compare which was better for returning fewer poisoned sites.

While Bing had fewer malicious results, Corrons was quick to point out cyber criminals will be more drawn to Google, simply because it is the most popular search engine.

"One thing for certain is that criminals are not focusing that much on Bing when compared to Google," Corrons said.

He also pointed to the quality and experience of security researchers at Microsoft.

"That helps a lot and is helping Bing be cleaner compared to Google," Corrons added.

"Google should try to [improve] as much as possible in avoiding this kind of stuff."

Conclusion... kind of

While the quicker results may aid Black Hat SEO attacks to some extent, in that results, including malicious ones, will be immediately accessible, it is hard to see how Google Instant places more power in the hands of cyber criminals.

Advertisement - Article continues below

Given that suggestions based on trending was already a feature in the previous version of Google and the search results are the same, hackers should not expect to get much more help with Instant than before.

Nevertheless, as Corrons suggested, the fight against this kind of attack should be something at the top of any search engine's priorities.

Featured Resources

Top 5 challenges of migrating applications to the cloud

Explore how VMware Cloud on AWS helps to address common cloud migration challenges

Download now

3 reasons why now is the time to rethink your network

Changing requirements call for new solutions

Download now

All-flash buyer’s guide

Tips for evaluating Solid-State Arrays

Download now

Enabling enterprise machine and deep learning with intelligent storage

The power of AI can only be realised through efficient and performant delivery of data

Download now
Advertisement

Recommended

Visit/cloud/cloud-backup/355025/google-backup-and-sync-review-that-syncing-feeling
cloud backup

Google Backup and Sync review: That syncing feeling

17 Mar 2020
Visit/security/355013/10-quick-tips-to-identifying-phishing-emails
Security

10 quick tips to identifying phishing emails

16 Mar 2020
Visit/business-strategy/mergers-and-acquisitions/354941/panda-security-to-be-acquired-by-watchguard
mergers and acquisitions

Panda Security to be acquired by WatchGuard

9 Mar 2020
Visit/mobile/google-android/354816/android-11-developer-access-arrives-earlier-than-expected
Google Android

Android 11 developer access arrives earlier than expected

20 Feb 2020

Most Popular

Visit/mobile/mobile-phones/355088/apple-lifts-iphone-purchase-restrictions
Mobile Phones

Apple lifts iPhone purchase restrictions

23 Mar 2020
Visit/software/operating-systems/355080/internal-docs-show-apple-is-aware-of-ios-13-hotspot-disconnect
operating systems

Report: Apple is aware of iOS 13 hotspot disconnect issue

23 Mar 2020
Visit/operating-systems/26138/how-to-speed-up-windows-10
operating systems

How to speed up Windows 10

4 Mar 2020
Visit/security/cyber-security/355041/critical-nhs-cyber-security-checks-suspended-due-to-coronavirus
cyber security

Critical NHS cyber security checks suspended due to coronavirus response

19 Mar 2020